Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium)
History

Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Tue, 20 Jan 2026 04:30:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published: 2026-01-20T04:14:15.784Z

Updated: 2026-01-20T04:14:15.784Z

Reserved: 2026-01-13T18:20:17.013Z

Link: CVE-2026-0903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-20T05:16:15.733

Modified: 2026-01-20T05:16:15.733

Link: CVE-2026-0903

cve-icon Redhat

No data.